APT / THREAT GROUP💰 FINANCIAL
blackfile
1
aliases
Intelligence Profile
blackfile — tracked by MISP Galaxy (ransomware).
Threat Analysis
blackfile is a known-sophistication threat actor of undetermined national origin, engaged in cyber operations with a primary motivation of financial.
Financially motivated threat actors like blackfile prioritize monetary gain through methods such as ransomware deployment, banking trojans, cryptocurrency theft, BEC scams, or credential harvesting for resale on underground markets.
Intelligence Reports Mentioning blackfile
Welcome to BlackFile: Inside a Vishing Extortion Operation
Mandiant Blog· May 15, 2026
Cybercrime Groups Using Vishing and SSO Abuse in Rapid SaaS Extortion Attacks
The Hacker News· May 1, 2026
BlackFile Group Targets Retail and Hospitality with Vishing Attacks
Infosecurity Magazine· Apr 27, 2026
New BlackFile extortion group linked to surge of vishing attacks
BleepingComputer· Apr 24, 2026
External References
Quick Facts
TypeAPT / Threat Group
Motivation💰 financial
Aliases1
Also Known As
blackfile
DLS Infrastructure
○ OFFLINEblacknbsxfdmjtx4yn533zzm4bemtdfl6dyopbmhg46ckhn4qy7i77id.onion
Research Links
Data sourced from Malpedia, Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Actor attribution is based on available intelligence and may be incomplete.